2020-08-26 07:56:23 +00:00
|
|
|
package model
|
|
|
|
|
|
|
|
import (
|
|
|
|
"encoding/json"
|
|
|
|
"github.com/caos/logging"
|
|
|
|
"github.com/caos/zitadel/internal/crypto"
|
|
|
|
es_models "github.com/caos/zitadel/internal/eventstore/models"
|
|
|
|
"github.com/caos/zitadel/internal/iam/model"
|
|
|
|
"github.com/lib/pq"
|
|
|
|
"reflect"
|
|
|
|
)
|
|
|
|
|
|
|
|
type OIDCIDPConfig struct {
|
|
|
|
es_models.ObjectRoot
|
2020-09-18 11:26:28 +00:00
|
|
|
IDPConfigID string `json:"idpConfigId"`
|
|
|
|
ClientID string `json:"clientId"`
|
|
|
|
ClientSecret *crypto.CryptoValue `json:"clientSecret,omitempty"`
|
|
|
|
Issuer string `json:"issuer,omitempty"`
|
|
|
|
Scopes pq.StringArray `json:"scopes,omitempty"`
|
|
|
|
IDPDisplayNameMapping int32 `json:"idpDisplayNameMapping,omitempty"`
|
|
|
|
UsernameMapping int32 `json:"usernameMapping,omitempty"`
|
2020-08-26 07:56:23 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func (c *OIDCIDPConfig) Changes(changed *OIDCIDPConfig) map[string]interface{} {
|
|
|
|
changes := make(map[string]interface{}, 1)
|
|
|
|
changes["idpConfigId"] = c.IDPConfigID
|
|
|
|
if c.ClientID != changed.ClientID {
|
|
|
|
changes["clientId"] = changed.ClientID
|
|
|
|
}
|
2020-09-18 11:26:28 +00:00
|
|
|
if c.ClientSecret != nil && c.ClientSecret != changed.ClientSecret {
|
2020-08-26 07:56:23 +00:00
|
|
|
changes["clientSecret"] = changed.ClientSecret
|
|
|
|
}
|
|
|
|
if c.Issuer != changed.Issuer {
|
|
|
|
changes["issuer"] = changed.Issuer
|
|
|
|
}
|
|
|
|
if !reflect.DeepEqual(c.Scopes, changed.Scopes) {
|
|
|
|
changes["scopes"] = changed.Scopes
|
|
|
|
}
|
2020-09-18 11:26:28 +00:00
|
|
|
if c.IDPDisplayNameMapping != changed.IDPDisplayNameMapping {
|
|
|
|
changes["idpDisplayNameMapping"] = changed.IDPDisplayNameMapping
|
|
|
|
}
|
|
|
|
if c.UsernameMapping != changed.UsernameMapping {
|
|
|
|
changes["usernameMapping"] = changed.UsernameMapping
|
|
|
|
}
|
2020-08-26 07:56:23 +00:00
|
|
|
return changes
|
|
|
|
}
|
|
|
|
|
|
|
|
func OIDCIDPConfigFromModel(config *model.OIDCIDPConfig) *OIDCIDPConfig {
|
|
|
|
return &OIDCIDPConfig{
|
2020-09-18 11:26:28 +00:00
|
|
|
ObjectRoot: config.ObjectRoot,
|
|
|
|
IDPConfigID: config.IDPConfigID,
|
|
|
|
ClientID: config.ClientID,
|
|
|
|
ClientSecret: config.ClientSecret,
|
|
|
|
Issuer: config.Issuer,
|
|
|
|
Scopes: config.Scopes,
|
|
|
|
IDPDisplayNameMapping: int32(config.IDPDisplayNameMapping),
|
|
|
|
UsernameMapping: int32(config.UsernameMapping),
|
2020-08-26 07:56:23 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func OIDCIDPConfigToModel(config *OIDCIDPConfig) *model.OIDCIDPConfig {
|
|
|
|
return &model.OIDCIDPConfig{
|
2020-09-18 11:26:28 +00:00
|
|
|
ObjectRoot: config.ObjectRoot,
|
|
|
|
IDPConfigID: config.IDPConfigID,
|
|
|
|
ClientID: config.ClientID,
|
|
|
|
ClientSecret: config.ClientSecret,
|
|
|
|
Issuer: config.Issuer,
|
|
|
|
Scopes: config.Scopes,
|
|
|
|
IDPDisplayNameMapping: model.OIDCMappingField(config.IDPDisplayNameMapping),
|
|
|
|
UsernameMapping: model.OIDCMappingField(config.UsernameMapping),
|
2020-08-26 07:56:23 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (iam *IAM) appendAddOIDCIDPConfigEvent(event *es_models.Event) error {
|
|
|
|
config := new(OIDCIDPConfig)
|
|
|
|
err := config.SetData(event)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
config.ObjectRoot.CreationDate = event.CreationDate
|
|
|
|
if i, idpConfig := GetIDPConfig(iam.IDPs, config.IDPConfigID); idpConfig != nil {
|
|
|
|
iam.IDPs[i].Type = int32(model.IDPConfigTypeOIDC)
|
|
|
|
iam.IDPs[i].OIDCIDPConfig = config
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (iam *IAM) appendChangeOIDCIDPConfigEvent(event *es_models.Event) error {
|
|
|
|
config := new(OIDCIDPConfig)
|
|
|
|
err := config.SetData(event)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
if i, idpConfig := GetIDPConfig(iam.IDPs, config.IDPConfigID); idpConfig != nil {
|
|
|
|
iam.IDPs[i].OIDCIDPConfig.SetData(event)
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (o *OIDCIDPConfig) SetData(event *es_models.Event) error {
|
|
|
|
o.ObjectRoot.AppendEvent(event)
|
|
|
|
if err := json.Unmarshal(event.Data, o); err != nil {
|
|
|
|
logging.Log("EVEN-Msh8s").WithError(err).Error("could not unmarshal event data")
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|